Integrate Kisi with OneLogin SSO
This is a Kisi-built integration, maintained and supported by Kisi.
As a Kisi organization owner you can set up OneLogin single sign-on (SSO) for your Kisi users. In addition to your SSO integration, you can:
- set up SCIM provisioning to easily and securely sync identities between your IdP and Kisi
- optionally enable authentication with password for individual users, providing flexibility as needed
Prerequisites
- a Kisi organization owner account
- a valid and activated SSO license
Before setting up the integration, ensure you are logged in as the Kisi organization owner and have a valid, activated SSO license. If these prerequisites are met and the SSO & SCIM option is still not visible on the dashboard, please reach out to Kisi Support for assistance.
Set up the integration in OneLogin
- Sign in to OneLogin
- At the top, select Applications and click on Add App
- Search for Kisi and click on the app
- Click Save to create the application
- Navigate to Configuration and enter your Kisi Domain. (You can find your Kisi organization domain in Kisi, under Settings > General)
- Navigate to SSO and copy the Issuer URL
- Click Save
Set up the integration in Kisi
- Sign in to Kisi as the organization owner
- Under Settings, click on SSO & SCIM
- Under Metadata URL, paste the Issuer URL you have previously copied in OneLogin
- Click Save
- Click on Generate Certificate. Now that you have generated the encryption certificate, go back to OneLogin and follow the steps below to complete the configuration.
Complete the configuration in OneLogin
- Under Configurations > SAML Encryption, in the Public key section, paste the contents of the encryption certificate you downloaded from Kisi
- Click Save
- Assign users to the created Kisi application
To further control your SSO integration, you can set up SCIM provisioning. This will help you to easily and securely sync identities between your IdP and Kisi.
Flexible authentication: SSO or password
Kisi organizations with Single Sign-On (SSO) enabled can, if needed, also enable authentication with password for users. If enabled, the user will be able to log in with email and password. If the user is in the organizations' IdP directory, an SSO login will also be available.
User removal impact on event logs
If you're utilizing a Single Sign-On (SSO) platform and an employee is removed, upon reviewing the Event history, the logs related to that user will continue displaying the user's name, even though they've been removed from the system.